CVE Database

46542+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0340
7.3 HIGH

A vulnerability classified as critical was found in code-projects Cinema Seat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jan 9, 2025
CVE-2024-53706
7.8 HIGH

A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to …

Jan 9, 2025
CVE-2024-53705
7.5 HIGH

A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on …

Jan 9, 2025
CVE-2025-0328
7.3 HIGH

A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by this issue is some unknown functionality …

Jan 9, 2025
CVE-2025-0306
7.4 HIGH

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages …

Jan 9, 2025
CVE-2024-13206
7.8 HIGH

A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveantivirus/tmp/reveinstall. The manipulation …

Jan 9, 2025
CVE-2024-13200
7.3 HIGH

A vulnerability, which was classified as critical, was found in wander-chu SpringBoot-Blog 1.0. This affects the function preHandle of the file src/main/java/com/my/blog/website/interceptor/BaseInterceptor.java of the component …

Jan 9, 2025
CVE-2024-27980
8.1 HIGH

Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution …

Jan 9, 2025
CVE-2025-0283
7.0 HIGH

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version …

Jan 8, 2025
CVE-2024-13189
7.3 HIGH

A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file src/main/java/com/wdd/myblog/config/MyBlogMvcConfig.java. The manipulation leads to …

Jan 8, 2025
CVE-2025-22141
8.8 HIGH

WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, specifically in the cargo parameter. This vulnerability …

Jan 8, 2025
CVE-2025-22140
8.8 HIGH

WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php endpoint, specifically in the id_dependente parameter. This vulnerability …

Jan 8, 2025
CVE-2025-0291
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Jan 8, 2025
CVE-2024-54818
8.8 HIGH

SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.

Jan 8, 2025
CVE-2025-21111
7.5 HIGH

Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this …

Jan 8, 2025
CVE-2024-56784
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Adding array index check to prevent memory corruption [Why & How] Array indices out …

Jan 8, 2025
CVE-2024-56775
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix handling of plane refcount [Why] The mechanism to backup and restore plane states …

Jan 8, 2025
CVE-2024-56772
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: kunit: string-stream: Fix a UAF bug in kunit_init_suite() In kunit_debugfs_create_suite(), if alloc_string_stream() fails in the …

Jan 8, 2025
CVE-2024-51442
8.8 HIGH

Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file.

Jan 8, 2025
CVE-2023-35685
7.8 HIGH

In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation …

Jan 8, 2025
CVE-2025-22130
8.8 HIGH

Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access …

Jan 8, 2025
CVE-2024-55656
8.8 HIGH

RedisBloom adds a set of probabilistic data structures to Redis. There is an integer overflow vulnerability in RedisBloom, which is a module used in Redis. …

Jan 8, 2025
CVE-2024-55517
8.8 HIGH

An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGController is …

Jan 8, 2025
CVE-2024-51737
7.0 HIGH

RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticated redis user executing FT.SEARCH or FT.AGGREGATE with a …

Jan 8, 2025
CVE-2024-51480
7.0 HIGH

RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYINDEX, TS.MGET, TS.MRAGE, TS.MREVRANGE by an authenticated user, using …

Jan 8, 2025
CVE-2025-21102
7.5 HIGH

Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this …

Jan 8, 2025
CVE-2024-11423
7.5 HIGH

The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, …

Jan 8, 2025
CVE-2024-12854
8.8 HIGH

The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the functionality that automatically extracts …

Jan 8, 2025
CVE-2024-12853
8.8 HIGH

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in …

Jan 8, 2025
CVE-2024-9939
7.5 HIGH

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it …

Jan 8, 2025
CVE-2024-45033
8.1 HIGH

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with …

Jan 8, 2025
CVE-2024-13186
7.5 HIGH

The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Jan 8, 2025
CVE-2024-13185
7.5 HIGH

The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Jan 8, 2025
CVE-2024-11939
7.5 HIGH

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ parameter in all versions up to, and …

Jan 8, 2025
CVE-2024-13173
7.5 HIGH

The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Jan 8, 2025
CVE-2024-11271
8.8 HIGH

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing capability check on several functions in …

Jan 8, 2025
CVE-2024-11270
8.8 HIGH

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function …

Jan 8, 2025
CVE-2024-56451
7.3 HIGH

Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-11916
7.4 HIGH

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability …

Jan 8, 2025
CVE-2024-11816
8.8 HIGH

The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing …

Jan 8, 2025
CVE-2024-56447
7.8 HIGH

Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56444
7.5 HIGH

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56439
7.5 HIGH

Access control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2025-22132
8.3 HIGH

WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the file upload functionality of the WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. By …

Jan 7, 2025
CVE-2024-53522
7.5 HIGH

Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to …

Jan 7, 2025
CVE-2022-45186
8.1 HIGH

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.

Jan 7, 2025
CVE-2022-45185
8.8 HIGH

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code …

Jan 7, 2025
CVE-2024-40427
7.9 HIGH

Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to execute

Jan 7, 2025
CVE-2024-55413
7.8 HIGH

A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via …

Jan 7, 2025
CVE-2024-55412
7.8 HIGH

A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via …

Jan 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.